Knowella

Anti-Bribery Risk Assessment Template

In the United Kingdom the risk assessment is not a supporting document for the anti-bribery programme. It is the foundation of the statutory defence, and since September 2025 it underpins three separate corporate offences rather than one. An organisation without a current, evidenced assessment has no defence to argue from.

KnowComplyAssessmentCMP-043Full guide
Underpins
Three UK failure to prevent defences
Reviewed
Annually and on change

Summary

In short

  • The UK now has three failure to prevent offences: bribery under the Bribery Act 2010, facilitation of tax evasion under the Criminal Finances Act 2017, and fraud under ECCTA, in force from 1 September 2025.
  • All three provide a procedures-based defence, and in each the risk assessment is what makes proportionality arguable. Without it there is nothing to calibrate the procedures against.
  • The Home Office guidance on failure to prevent fraud is more prescriptive than the earlier bribery and tax evasion guidance, and it states explicitly that risk assessment is the foundation for the other five principles.
  • Being regulated elsewhere does not mean your existing procedures automatically qualify. The guidance is clear that existing compliance mechanisms are a starting point, not a defence.
  • The failure to prevent fraud offence carries an unlimited fine, applies to large organisations across all sectors, and requires no proof of management involvement.
  • Smaller organisations are affected indirectly: they may be associated persons of large organisations and face contractual requirements flowed down to them.

What it is

What it is

What is an anti-bribery risk assessment?

A structured assessment of where an organisation is exposed to bribery and corruption, by geography, sector, transaction type, business model and third party relationship, and what controls address each exposure. It informs the design of the whole programme, and under UK law it is the element on which the statutory defence rests.

Why does the assessment matter so much legally?

Because the UK failure to prevent offences provide a defence only where procedures were adequate or reasonable, and both standards are judged as proportionate to risk. Proportionality cannot be demonstrated without an assessment establishing what the risk was. Home Office guidance on the fraud offence states directly that a thorough risk assessment is the foundation and that all other principles should be informed by it.

When to use it

When to use it, and when not to

The assessment establishes exposure and calibrates the programme. It is not the programme, and it is not the due diligence performed on individual counterparties.

Use it for

  • Establishing the organisation-wide exposure by geography, sector, transaction type and business model
  • Assessing third party exposure: agents, distributors, consultants, customs brokers and joint venture partners
  • Reviewing after entering a new market, acquiring a business, or changing the intermediary model
  • Calibrating due diligence depth, approval thresholds and monitoring intensity to the assessed risk
  • Evidencing proportionality for the statutory defences under UK failure to prevent offences

Not for

  • Individual counterparty due diligence, which applies the assessment's conclusions to a specific third party
  • The code of conduct and gifts and hospitality policy, which are controls the assessment informs
  • Whistleblowing arrangements, which are a separate mechanism with their own requirements
  • Payment and procurement fraud controls, which address a different offence with overlapping controls
  • Sanctions and export control screening, which is a distinct regime with strict liability characteristics

Standards

What it is built against

Anti-bribery obligations combine a management system standard with criminal offences whose defences turn on the quality of the risk assessment.

ClauseRequirementWhere it lands
ISO 37001 cl.4.5Bribery risk assessment identifying, analysing, evaluating and prioritising bribery risk, reviewed regularlyExposure
Bribery Act 2010 s.7Corporate offence of failure to prevent bribery, with adequate procedures as the defenceHeader
Bribery Act guidance, principle 3Risk assessment as one of six principles underpinning adequate proceduresExposure
Criminal Finances Act 2017 ss.45-46Failure to prevent facilitation of UK and foreign tax evasion, with reasonable procedures as the defenceHeader
ECCTA 2023, failure to prevent fraudIn force 1 September 2025 for large organisations, with reasonable procedures as the only defenceHeader
FCPA anti-bribery and accounting provisionsProhibition on corrupt payments to foreign officials, plus books and records and internal controlsControls
ISO 37001 cl.8.2Due diligence on transactions, projects, business associates and personnel proportionate to assessed riskControls
ISO 37001 cl.9.2Internal audit of the anti-bribery management system at planned intervalsAssurance

What it does not cover

  • Counterparty due diligence, which applies the assessment to a specific third party before engagement.
  • Gifts, hospitality and facilitation payment policy, which are controls calibrated by the assessment.
  • Whistleblowing arrangements, which operate independently and have their own protections and timescales.
  • Sanctions and export control screening, a separate regime with different liability characteristics.
  • The books and records controls required under the FCPA accounting provisions, which sit with finance.

Filling it in

Filling it in well

An assessment that supports a legal defence has to show its working. Four things determine whether it does.

Assess by transaction, not only by geography

Identify the specific interactions where bribery is plausible: permits, licences, inspections, customs clearance, tender processes, tax settlements and anything mediated by an agent paid on outcome. Then establish who performs them, through whom, and with what oversight. A country risk score tells you the weather; this tells you where the exposure sits.

Cover associated persons explicitly

All three UK offences turn on acts by associated persons: employees, agents, subsidiaries, and anyone performing services for or on behalf of the organisation. The assessment has to reach them, and the guidance is clear that smaller organisations may find themselves subject to requirements flowed down contractually because they are associated persons of someone larger.

Do not assume existing compliance covers it

The Home Office guidance states that organisations should not duplicate existing work, and equally that existing regulatory compliance mechanisms do not automatically amount to reasonable procedures. The correct approach is to map what exists against the risks this assessment identified and to record where the gaps are, rather than asserting that a regulated business is therefore compliant.

Date it, own it, and review it on change

The defence is judged on procedures in place at the time of the offence. An assessment dated four years ago, covering a business that has since entered two markets and acquired a distributor, does not support proportionality for the current operation. Review annually and on any material change to markets, model or intermediaries.

Audit findings

Common audit findings

Findings here concern whether the assessment could actually support a defence.

FindingClauseWhat fixes it
Assessment based on country risk indices with no transaction-level analysis.ISO 37001 cl.4.5Identify the specific transactions and intermediaries where exposure arises.
Third parties and associated persons not covered.Bribery Act s.7All three UK offences turn on associated persons; the assessment must reach them.
Existing regulatory compliance cited as evidence of reasonable procedures.ECCTA guidanceMap existing controls against identified risks and record gaps; regulation is not a defence.
Assessment not reviewed after entering a new market or acquiring a business.ISO 37001 cl.4.5Review on change; the defence is judged on procedures at the time of the offence.
Due diligence depth uniform rather than calibrated to assessed risk.ISO 37001 cl.8.2Tier due diligence; uniform depth over-burdens low risk and under-examines high risk.
Fraud risk not assessed despite the September 2025 offence.ECCTAExtend the assessment to fraud committed for the organisation's benefit; it is a separate offence.
No top level commitment evidenced beyond a signed policy.Bribery Act guidance, principle 1Evidence engagement: resourcing decisions, escalations handled, communication from leadership.
Training generic rather than targeted at the assessed high-risk roles.ISO 37001 cl.7.3Target training at people performing the transactions the assessment identified.
Monitoring and review principle unaddressed.Bribery Act guidance, principle 6Define what is monitored, how often, and what happens when something is found.
Assessment undated or unowned.ISO 37001 cl.4.5Date, sign and own it; an undated assessment cannot evidence procedures at a point in time.

Worked case

Case in point: the third offence nobody assessed for

The UK now has three failure to prevent offences. Bribery came first under the Bribery Act 2010, with adequate procedures as the defence. Facilitation of tax evasion followed under the Criminal Finances Act 2017, with reasonable procedures. The failure to prevent fraud offence under ECCTA came into force on 1 September 2025, applying to large organisations across all sectors, carrying an unlimited fine, with reasonable procedures as the only defence.

The Home Office guidance published in November 2024 was described by practitioners as remarkably prescriptive relative to its predecessors, and it states plainly that a thorough risk assessment is the foundation and that the other five principles should be informed by its results. The Serious Fraud Office signalled its intention to pursue the offence from the outset.

Many organisations arrived at September 2025 with a bribery risk assessment reviewed reasonably recently and no assessment at all of where fraud might be committed for the organisation's benefit. Those are overlapping but distinct exposures, and only one of them had been mapped.

Definitions

Definitions and key terms

Associated person
Anyone performing services for or on behalf of the organisation: employees, agents, subsidiaries, contractors and intermediaries.
Adequate procedures
The Bribery Act 2010 section 7 defence standard, judged against six principles and proportionate to risk.
Reasonable procedures
The defence standard under the tax evasion and fraud offences. The Home Office has indicated it is no more onerous than adequate.
Facilitation payment
A small payment to secure or expedite a routine government action. Illegal under the Bribery Act; a narrow FCPA exception exists.
Six principles
Top level commitment, risk assessment, proportionate risk-based procedures, due diligence, communication including training, and monitoring and review.
Failure to prevent offence
A corporate offence turning on an associated person's act, without requiring proof of management knowledge or intent.
Red flag
An indicator warranting enhanced scrutiny: unusual commission, request for payment to a third country, political connection, refusal of contract terms.
Books and records provisions
FCPA accounting requirements for accurate records and adequate internal accounting controls, enforced independently of bribery itself.

FAQ

Frequently asked questions

Why is the risk assessment the foundation of the defence?+

Because the defences require procedures that are adequate or reasonable, and both are judged as proportionate to the risk faced. Proportionality is unarguable without an assessment establishing what the risk was. Home Office guidance on the fraud offence states directly that a thorough risk assessment is the foundation and that the other principles should be informed by its results.

What changed on 1 September 2025?+

The failure to prevent fraud offence under the Economic Crime and Corporate Transparency Act 2023 came into force in England and Wales. It applies to large organisations across all sectors, makes them criminally liable where an associated person commits fraud intending to benefit the organisation, carries an unlimited fine, and provides reasonable fraud prevention procedures as the only defence. It requires no proof of management involvement.

Do our existing compliance procedures count?+

They are a starting point, not a defence. The guidance advises against duplicating existing work while making clear that existing regulatory compliance mechanisms do not automatically amount to reasonable procedures. The correct approach is to map what you have against the risks identified in this assessment and record where the gaps are.

Are small organisations affected?+

Directly, only where they meet the large organisation threshold. Indirectly, substantially: a smaller business may be an associated person of a large organisation and find fraud prevention requirements flowed down contractually. The practical effect is that the obligation propagates through supply chains well beyond the entities in scope.

How often should the assessment be reviewed?+

Annually as a minimum, and on any material change: entering a new market, acquiring a business, changing the intermediary model, or a significant change in the regulatory environment. The defence is judged on the procedures in place at the time of the offence, so an assessment describing a business you no longer are supports nothing.

The agents

What the agents do with it

The assessment is the foundation of three defences. What fails is the transaction detail nobody mapped and the review that lapsed after an acquisition.

KnowComply

Holds the assessment against markets, transaction types and third parties, and triggers review on acquisitions, new markets and intermediary changes.

Ella

Maps existing controls against assessed risks and surfaces the gaps, rather than allowing existing compliance to be asserted as coverage.

KnowContractor

Extends assessment and due diligence to associated persons, including agents and intermediaries who are not suppliers in the usual sense.

KnowTrain

Targets training at the roles performing the transactions the assessment identified, rather than delivering the same module to everyone.

This template lives in KnowComplyaudit and governance. Audit programmes, legal register, management review, risk and certification.

Sources

Sources

Start in Minutes, Not Weeks

Launch a Ready-Made Template and Customize It Your Way

Every template is fully editable. Adjust fields, workflows, and branding to match your processes, then deploy to your team instantly.